Vulnerabilities (CVE)

Filtered by vendor Gsheetconnector Subscribe
Filtered by product Woocommerce Google Sheet Connector
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1562 1 Gsheetconnector 1 Woocommerce Google Sheet Connector 2025-03-07 N/A 5.3 MEDIUM
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.
CVE-2023-2329 1 Gsheetconnector 1 Woocommerce Google Sheet Connector 2024-11-21 N/A 8.8 HIGH
The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack